0Pricing
FastAPI Backend Development Bootcamp · 강의

CORS, CSP 및 보안 헤더 정책

정상적인 클라이언트를 방해하지 않으면서 교차 출처 접근을 제한하고 강화된 보안 헤더를 주입합니다.

CORS, CSP 및 보안 헤더 정책은(는) CoddyKit의 무료 FastAPI Backend Development Bootcamp 강의입니다. 이것은 4개 중 4번째 강의입니다. 아래에서 전체 강의를 무료로 읽을 수 있으며, 내장 코드 에디터와 24/7 AI 튜터와 함께 브라우저에서 직접 실습할 수 있습니다. 이 강의는 FastAPI Backend Development Bootcamp 학습 경로의 일부이며, 진행 상황이 웹과 CoddyKit 앱에 동기화됩니다. FastAPI Backend Development Bootcamp 강의에는 총 4개의 강의가 포함되어 있습니다.

이 강의의 일부는 아직 번역되지 않았으며 영어로 표시됩니다.

Why Headers Are Your Outer Perimeter

Before a request ever reaches your business logic, the browser and your server negotiate trust through HTTP headers. Two families dominate API hardening:

  • CORS (Cross-Origin Resource Sharing) decides which browser origins may read your responses.
  • Security response headers (CSP, HSTS, X-Frame-Options, etc.) tell the browser how to constrain the page it renders.

The goal of this lesson is to lock down cross-origin access and inject hardened headers without breaking legitimate clients. Misconfigure them and you either leak data to any website or block your own frontend.

The CORS Mental Model

CORS is enforced by the browser, not your server. Your API simply emits Access-Control-* headers; the browser decides whether to expose the response to JavaScript.

  • A simple request (GET/POST with safe headers) is sent immediately; the browser checks Access-Control-Allow-Origin on the response.
  • A preflight OPTIONS request is sent first for non-simple methods (PUT, DELETE) or custom headers like Authorization.

Critically: CORS does not protect server-to-server calls, curl, or mobile apps. It is purely a browser same-origin relaxation mechanism.

Configuring CORSMiddleware

FastAPI ships Starlette's CORSMiddleware. The cardinal rule: never combine allow_origins=["*"] with allow_credentials=True — the browser rejects that pairing, and it would be a data-leak anyway.

Pin an explicit allow-list of origins instead of a wildcard.

from fastapi import FastAPI
from fastapi.middleware.cors import CORSMiddleware

app = FastAPI()

app.add_middleware(
    CORSMiddleware,
    allow_origins=[
        "https://app.example.com",
        "https://admin.example.com",
    ],
    allow_credentials=True,
    allow_methods=["GET", "POST", "PUT", "DELETE"],
    allow_headers=["Authorization", "Content-Type"],
    max_age=600,
)

Wildcards, Credentials and Regex

When you must accept many subdomains, do not fall back to "*". Use allow_origin_regex so the browser still gets back the exact origin it sent, which is required for credentialed requests.

  • allow_methods=["*"] and allow_headers=["*"] are tolerable, but only when allow_credentials=False.
  • With credentials on, every value must be explicit or regex-matched.
from fastapi import FastAPI
from fastapi.middleware.cors import CORSMiddleware

app = FastAPI()

app.add_middleware(
    CORSMiddleware,
    allow_origin_regex=r"https://([a-z0-9-]+)\.example\.com",
    allow_credentials=True,
    allow_methods=["*"],
    allow_headers=["Authorization", "Content-Type"],
    expose_headers=["X-Request-ID"],
)

Validating an Origin Allow-List in Pure Python

The logic CORS middleware runs is conceptually simple: reflect the request origin only if it passes validation. Here is a standalone validator you could unit-test, mirroring how a custom origin check behaves before any framework is involved.

import re

ALLOWED = {"https://app.example.com", "https://admin.example.com"}
SUBDOMAIN = re.compile(r"^https://[a-z0-9-]+\.example\.com$")


def resolve_allow_origin(origin: str) -> str | None:
    if origin in ALLOWED or SUBDOMAIN.match(origin):
        return origin  # echo exact origin back
    return None  # do not emit Access-Control-Allow-Origin


for test in [
    "https://app.example.com",
    "https://team-7.example.com",
    "https://evil.com",
    "http://app.example.com",
]:
    print(test, "->", resolve_allow_origin(test))

Hardening Headers with a Custom Middleware

CORS handles cross-origin reads; a separate middleware injects defensive headers on every response. The essentials:

  • Strict-Transport-Security (HSTS) forces HTTPS.
  • X-Content-Type-Options: nosniff stops MIME sniffing.
  • X-Frame-Options: DENY blocks clickjacking.
  • Referrer-Policy limits leaked URLs.
from starlette.middleware.base import BaseHTTPMiddleware

HEADERS = {
    "Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
    "X-Content-Type-Options": "nosniff",
    "X-Frame-Options": "DENY",
    "Referrer-Policy": "strict-origin-when-cross-origin",
    "Permissions-Policy": "geolocation=(), microphone=(), camera=()",
}


class SecurityHeadersMiddleware(BaseHTTPMiddleware):
    async def dispatch(self, request, call_next):
        response = await call_next(request)
        for key, value in HEADERS.items():
            response.headers.setdefault(key, value)
        return response


app.add_middleware(SecurityHeadersMiddleware)

Content-Security-Policy Fundamentals

CSP is the most powerful header for stopping XSS. It tells the browser which sources are allowed for scripts, styles, images, and connections. For an API serving JSON, a very tight default works because no inline content is rendered.

  • default-src 'none' denies everything unless overridden.
  • frame-ancestors 'none' is the modern replacement for X-Frame-Options.
  • For HTML pages, prefer a nonce over 'unsafe-inline'.
API_CSP = "; ".join([
    "default-src 'none'",
    "frame-ancestors 'none'",
    "base-uri 'none'",
    "form-action 'none'",
])

# Attach on the security middleware:
# response.headers.setdefault("Content-Security-Policy", API_CSP)
print(API_CSP)

Nonce-Based CSP for HTML Responses

When your FastAPI app renders HTML (docs, an admin page), inline scripts need a per-response nonce. Generate a fresh random nonce on each request, place it in both the CSP header and the <script nonce=...> tag.

Here is the standalone nonce-generation logic you would reuse inside a request handler.

import secrets


def new_nonce() -> str:
    return secrets.token_urlsafe(16)


def csp_with_nonce(nonce: str) -> str:
    return "; ".join([
        "default-src 'self'",
        f"script-src 'self' 'nonce-{nonce}'",
        "style-src 'self'",
        "object-src 'none'",
        "frame-ancestors 'none'",
    ])


n = new_nonce()
print("nonce:", n)
print(csp_with_nonce(n))

Report-Only Rollout Without Breaking Clients

Deploying a strict CSP blindly will break legitimate pages. The safe path is Content-Security-Policy-Report-Only: the browser does not enforce the policy but reports violations to an endpoint you control.

  • Ship report-only first, collect violations for days.
  • Tighten directives until reports go quiet, then switch to the enforcing header.

This is the single most important practice for not locking out real users.

from fastapi import FastAPI, Request, Response

app = FastAPI()

CSP = "default-src 'self'; report-uri /csp-report"


@app.middleware("http")
async def csp_report_only(request: Request, call_next):
    response: Response = await call_next(request)
    response.headers.setdefault("Content-Security-Policy-Report-Only", CSP)
    return response


@app.post("/csp-report")
async def collect(request: Request):
    payload = await request.json()
    # log payload["csp-report"] to your SIEM
    return Response(status_code=204)

Preflight, Caching and Performance

Each non-simple cross-origin call triggers a preflight OPTIONS round-trip. Tune it so you stay secure but fast:

  • Set max_age (emitted as Access-Control-Max-Age) so browsers cache the preflight result. Chromium caps it at 2 hours.
  • Keep allow_headers minimal — every custom header forces a preflight.
  • Avoid adding Authorization to simple GETs if you can pass it another safe way; otherwise expect a preflight.

Order matters in Starlette: middleware added last runs first (outermost). Add CORS so it wraps your security-header middleware, letting preflights short-circuit cleanly.

Putting It All Together

A hardened FastAPI bootstrap layers the pieces in the right order: security headers innermost, CORS outermost, with explicit origins and a tight CSP. This is the template you would deploy to production.

from fastapi import FastAPI
from fastapi.middleware.cors import CORSMiddleware
from starlette.middleware.base import BaseHTTPMiddleware

SEC = {
    "Strict-Transport-Security": "max-age=63072000; includeSubDomains; preload",
    "X-Content-Type-Options": "nosniff",
    "Referrer-Policy": "strict-origin-when-cross-origin",
    "Content-Security-Policy": "default-src 'none'; frame-ancestors 'none'",
}


class SecHeaders(BaseHTTPMiddleware):
    async def dispatch(self, request, call_next):
        resp = await call_next(request)
        for k, v in SEC.items():
            resp.headers.setdefault(k, v)
        return resp


app = FastAPI()
app.add_middleware(SecHeaders)            # added first -> runs inner
app.add_middleware(                        # added last  -> runs outer
    CORSMiddleware,
    allow_origins=["https://app.example.com"],
    allow_credentials=True,
    allow_methods=["GET", "POST", "PUT", "DELETE"],
    allow_headers=["Authorization", "Content-Type"],
    max_age=600,
)

Quick Check: Credentialed CORS

Your React frontend at https://app.example.com sends authenticated requests with cookies, so it needs allow_credentials=True. What is the correct origin configuration?

Recap and Takeaways

You hardened the request perimeter without locking out real clients:

  • CORS is browser-enforced: use an explicit allow-list or allow_origin_regex, and never pair "*" with allow_credentials=True.
  • Security headers (HSTS, nosniff, Referrer-Policy, Permissions-Policy) belong on every response via a small middleware.
  • CSP is your strongest anti-XSS control: default-src 'none' for JSON APIs, nonce-based policies for HTML.
  • Roll out CSP with Report-Only first, watch violations, then enforce.
  • Tune max_age and minimal allow_headers to keep preflights cheap, and remember middleware order: added last runs outermost.

Secure defaults plus a measured rollout is how you ship hardening that production traffic survives.

자주 묻는 질문

“CORS, CSP 및 보안 헤더 정책” 강의는 무료인가요?

네 — “CORS, CSP 및 보안 헤더 정책” 전체 내용을 이 웹사이트에서 무료로 읽을 수 있습니다. 인터랙티브하게 실습하려면(내장 코드 에디터와 24/7 AI 튜터), CoddyKit PRO로 업그레이드하면 FastAPI Backend Development Bootcamp 강의 전체를 잠금 해제할 수 있습니다. FastAPI Backend Development Bootcamp 강의에는 총 4개의 강의가 포함되어 있습니다.

“CORS, CSP 및 보안 헤더 정책”에서 뭘 배우나요?

정상적인 클라이언트를 방해하지 않으면서 교차 출처 접근을 제한하고 강화된 보안 헤더를 주입합니다. 브라우저에서 직접 실행하는 실습 코드로 FastAPI Backend Development Bootcamp을(를) 배우며, 24/7 AI 튜터가 강의를 진행하면서 질문에 답변해줍니다.

FastAPI Backend Development Bootcamp을(를) 시작하는 데 경험이 필요한가요?

사전 경험은 필요하지 않습니다. CoddyKit의 FastAPI Backend Development Bootcamp은(는) 초급자부터 고급 학습자까지를 위해 구성되어 있으므로, 여기서 시작하거나 처음부터 시작할 수 있으며 자신의 속도대로 진행할 수 있습니다. 이것은 4개 중 4번째 강의입니다.

“CORS, CSP 및 보안 헤더 정책” 강의는 얼마나 걸리나요?

대부분의 CoddyKit 강의는 약 5~10분이 소요됩니다. 각 강의는 간결하고 인터랙티브하여 꾸준한 진행이 가능하며, 웹과 앱에서 중단한 부분부터 바로 시작할 수 있습니다.

이 FastAPI Backend Development Bootcamp 강의에서 코드를 작성하고 실행할 수 있나요?

네. 모든 FastAPI Backend Development Bootcamp 강의에는 내장 코드 에디터가 포함되어 있으므로, 브라우저에서 바로 실제 코드를 작성하고 실행한 후 즉시 AI 피드백을 받을 수 있습니다 — 로컬 설정이 필요 없습니다.

이 강의의 모든 강의

  1. OWASP API 보안 상위 10개 위협 완화
  2. 요청률 제한과 봇 악용 방지
  3. 비밀 관리와 키 순환
  4. CORS, CSP 및 보안 헤더 정책
← FastAPI Backend Development Bootcamp(으)로 돌아가기